The short version: with your own API keys, SideZero has no server in the middle — your pages and prompts go from your browser straight to your AI provider. Verify the wiring yourself.
On the free and paid Zero plans, your messages pass through our relay to the model provider and are never stored, logged, or read — we record only how much you used (token counts), which you can see in your account.
What we store for account holders: your name, email and avatar from Google sign-in; your plan; usage counts; email preferences. Deleting your account removes all of it immediately, with one narrow exception we state openly: if you were referred (or referred someone), we keep a one-way cryptographic fingerprint of the email involved — it cannot be turned back into your address, and it exists only so referral bonuses stay one-per-person. Usage rows are anonymized, and they never contained your content in the first place.
Cookies: a session cookie (sign-in), and — only if you arrive through a share link — a referral-code cookie for up to 30 days so the bonus can be credited. No third-party or advertising cookies.
Email: account holders get transactional email (welcome, purchase receipt) and at most one review request ever; marketing-type email has an unsubscribe link and honors it. Uninstall feedback you choose to send is stored and forwarded to our support inbox.
The support form: what you write, the address you give us and the category you pick are stored so the message cannot be lost, and forwarded to our support inbox. Say the word and we delete it. The form runs one bot check from Cloudflare (Turnstile) before it sends — that is a challenge, not an analytics tracker, and it is the only third-party request on this site.
How it is protected: every connection to sidezero.app uses HTTPS, and our database is not reachable from the public internet. We store no passwords at all — sign-in is delegated to Google, so there is no password of yours for us to lose. Access to the servers is limited to the one person who runs them. Your API keys are held by your browser and are never sent to us, and message content is never written down, so the strongest protection we can offer is simply that most of this data is never in our hands.
If you are in the EU or the UK: on your own API key we are not a data controller for your content at all — it never reaches us. For account data (your name, email and avatar from Google sign-in, your plan, usage counts, email preferences) we are the controller, and the basis is the contract you have with us for the service — plus, for the one-way email fingerprint described above, our legitimate interest in keeping referral bonuses to one per person. That account data is stored on servers in the United States. You can access, correct, export or delete it, object to or restrict how we use it, and complain to your local data-protection authority. Deletion you can do yourself, immediately, from your account page; for anything else email support@sidezero.app and a human will action it.
No analytics trackers, no ads, no data sales. Ever.
SideZero is made by CurrencyWiki Technologies LLC in San Diego, California.
Questions: support@sidezero.app